Integrate, manage and secure the AI you run — one machine or a whole estate. Self-hosted, one ground truth: Claude Code at the deepest level, Codex and Grok Build alongside. Honest about its limits.
These docs are organized with the Diátaxis
framework — four modes, each answering a different need. Pick the one that
matches what you are trying to do.
TutorialsLearning-oriented. Run the single binary and reach a populated read/write access graph, step by step.
How-to guidesTask-oriented. Connect a source, self-host, install air-gapped, verify a release, forward audit to Splunk.
ReferenceInformation-oriented. The REST API, the event bus (AsyncAPI), the modules, the CLI and configuration.
ExplanationUnderstanding-oriented. Architecture, the access graph, the security & threat model, licensing.
Olivares AI integrates, manages and secures the AI you run — on one machine or across
a whole estate, one ground truth: Claude Code at the deepest level, Codex and Grok Build
alongside, complementing those agents rather than competing. A single
self-hosted binary gives your AI the context, resource access and managed sessions it
needs to do real work, and gives you the granular permissions, policies,
budgets and audit evidence to run all of it — models, agents, MCP servers, the identities
behind them and the data they touch — across your infrastructure. It still shows you a
read/write access map of what each one can reach and the drift between Permitted and
Observed; all self-hosted, with no mandatory telemetry and no control-plane egress
by default — what crosses your perimeter is what you configure to cross it: calls to
your model APIs, the SIEM/webhook outputs you wire, an external embedding provider if you
provision one — and honest about what runs today versus what is pre-v1.
Honest by design
We document what runs today and what is pre-v1. Tutorial commands are tested;
where the contract does not yet cover something, the docs say so. See
Honesty & limits.
Open core
The product (engine, modules, web) is AGPL-3.0-only; the SDK and connectors
are Apache-2.0; enterprise modules are commercial. See
Open core & licensing.
Access map — What each agent reads and writes across your estate — origins on the left, the resources they touch on the right, R/RW by color.Least-privilege drift — Overlay the least-privilege diff: highlight unexpected access (observed, not permitted) and unused grants.Orchestration & A2A — Agent-to-agent topology — who delegates to whom, the live delegation flows, and declared cadences. Reads of the communication graph are privileged and self-audited.Inventory — Every agent, session, MCP, model and identity discovered across your estate.Observability & interop — Standards-based ingestion health and ledger-correlated trace drill-down. Figures are engine-wide (process-global), not per-tenant; standards are pinned to the versions and maturities the upstream bodies declare.Executive overview — Cost, usage, risk and compliance at a glance — drill down to the operational view for the detail.Overview — Your AI estate at a glance — inventory, activity, risk, compliance, spend and health.Security & forensics — Guardrail findings, the enforcement posture, the anomaly queue and tamper-evident incident forensics. The plane is detective by default — it records, it does not block on its own unless enforcement is enabled and governed.Session Recording Viewer — Unified timeline of agent activity and governance evidence for a single session.Identity & NHI — SSO, SCIM, identity inventory, the NHI lifecycle, the WIF graph and privileged login — observed, governed and audited.Data, knowledge & context — Governed knowledge bases, retrieval lineage, the prompt registry, agent memory and context policies.Plan — Planning the change. Nothing is written in this step.Kill switch — The estate emergency stop: one click halts every governed actuation surface. Engaging is deliberately cheap; recovery requires two distinct user accounts and a forced post-review.